CVE-2026-63073
CVE-2026-63073 — Untrusted Sender DN Used as Format String in CMP Response Validation
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. CWE: CWE-134 (Use of Externally-Controlled Format String) Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.
Published Updated Sources: NVD, OpenSSL (CNA), GitHub, SOCRadar CTI
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
ahead of 0% of scored CVEs
CVSS base
Unscored
no source published a base score
Remediation
The vendor's own words where we have them.
Upgrade OpenSSL to a fixed release. Apply vendor patches per advisory and restrict external exposure of the affected component until patched.
First 24 hours
Ordered from the record's own fields — exposure first, because you cannot patch what you have not found.
- Identify exposed assets running affected vendor/product/version combinations.
- Prioritize based on EPSS, PoC availability, and external exposure.
- Search available logs for exploit probes, errors, authentication anomalies, or suspicious child processes matching the vulnerability class.
Affected scope
Vendor, product and version as the advisories word them.
| Vendor | Product | Versions | Status |
|---|---|---|---|
| OpenSSL | OpenSSL | 4.0.0 to < 4.0.2 | Vulnerable |
| OpenSSL | OpenSSL | 3.6.0 to < 3.6.4 | Vulnerable |
| OpenSSL | OpenSSL | 3.5.0 to < 3.5.8 | Vulnerable |
| OpenSSL | OpenSSL | 3.4.0 to < 3.4.7 | Vulnerable |
What this weakness leads to
MITRE's own consequences and mitigations for the weakness class — the authority's wording, not guidance derived from the CVSS vector.
CWE-134 · Use of Externally-Controlled Format String
- Read Memory
- Modify Memory
- Execute Unauthorized Code or Commands
Mitigation: Choose a language that is not subject to this flaw.
Weakness & attack patterns
- CWE-134
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
Timeline
What happened to this CVE, newest first — with the readings a source repeats on a schedule counted underneath rather than listed.
- 2026
Initial · CVE published
Aug 25, 2026 · NVD
References
5 on the record
- github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca
Exploit, Third Party Advisory, Mitre
- github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29
Exploit, Third Party Advisory, Mitre
- github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21
Exploit, Third Party Advisory, Mitre
- github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4
Exploit, Third Party Advisory, Mitre
- openssl-library.org/news/secadv/20260825.txt
Vendor Advisory, Mitre
Elsewhere on this site
- OpenSSLevery CVE for this vendor
- Unclassifiedsame class
- CWE-134other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.
Answered from this record1
What should defenders know first?
CVE-2026-63073 is Untrusted Sender DN Used as Format String in CMP Response Validation, a unscored vulnerability affecting OpenSSL from OpenSSL. The current evidence does not list it in CISA KEV, and the exploit status is: Active exploitation is not confirmed from current sources for CVE-2026-63073. Public exploit evidence is: A public PoC is not confirmed from current sources for CVE-2026-63073. The affected-version evidence is listed in the key facts and affected products tables. Defenders should first verify whether exposed or business-critical assets run those versions, then apply vendor patches or mitigations, restrict reachable attack surface, and preserve logs for detection review. CVSS null describes technical severity, while EPSS 0% helps estimate near-term exploit likelihood; neither replaces asset context. Unknown fields should remain explicit in tickets, and threat actor, IOC, victimology, or payload claims should not be added unless a cited source supports them. Monitor CISA KEV, vendor advisories, NVD changes, public PoC repositories, and internal telemetry for update triggers.